Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ThemeFusion — Vulnerabilities & Security Advisories 50

Browse all 50 CVE security advisories affecting ThemeFusion. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ThemeFusion operates primarily as a developer of WordPress themes and plugins, most notably the Avada framework, which powers a significant portion of the web. Security audits reveal a concerning history, with 36 recorded Common Vulnerabilities and Exposures (CVEs) associated with its ecosystem. These flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from insufficient input validation and improper sanitization of user-supplied data within plugin functionalities. While the company maintains an active support channel for patching, the sheer volume of disclosed issues highlights systemic weaknesses in their development lifecycle. Recent incidents have largely focused on unauthenticated access vectors that allow attackers to execute arbitrary commands or hijack administrative sessions. This pattern suggests that while the software is widely adopted, its security posture has historically lagged behind industry standards, requiring rigorous third-party scrutiny and immediate updates to mitigate exploitation risks.

Found 9 results / 50 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-84925 Avada | Website Builder For WordPress & WooCommerce <= 7.16.1 - Reflected Cross-Site Scripting via 'lang' Parameter — Avada | Website Builder For WordPress & WooCommerce CWE-79 6.1 Medium 2026-10-02
CVE-2024-13346 Avada Theme <= 7.11.13 - Unauthenticated Arbitrary Shortcode Execution — Avada | Website Builder For WordPress & WooCommerce CWE-94 7.3 High 2025-02-13
CVE-2024-2311 Avada <= 7.11.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode — Avada | Website Builder For WordPress & WooCommerce CWE-79 6.4 Medium 2024-04-09
CVE-2024-2344 Avada <= 7.11.6 - Authenticated (Admin+) SQL Injection via entry — Avada | Website Builder For WordPress & WooCommerce CWE-89 7.2 High 2024-04-09
CVE-2024-2340 Avada <= 7.11.6 - Unauthenticated Sensitive Information Exposure via Form Uploads Directory Listing — Avada | Website Builder For WordPress & WooCommerce CWE-548 5.3 Medium 2024-04-09
CVE-2024-2343 Avada <= 7.11.6 - Authenticated (Contributor+) Server-Side Request Forgery via form_to_url_action — Avada | Website Builder For WordPress & WooCommerce CWE-918 6.4 Medium 2024-04-09
CVE-2024-1668 Avada <= 7.11.5 - Authenticated(Contributor+) Sensitive Information Exposure via Form Entries — Avada | Website Builder For WordPress & WooCommerce CWE-284 6.5 Medium 2024-03-13
CVE-2024-1468 Avada | Website Builder For WordPress & WooCommerce <= 7.11.4 - Authenticated (Contributor+) Arbitrary File Upload — Avada | Website Builder For WordPress & WooCommerce CWE-434 8.8 High 2024-02-29
CVE-2020-36711 Avada <= 6.2.2 - Authenticated (Contributor+) Cross-Site Scripting — Avada | Website Builder For WordPress & WooCommerce CWE-79 6.4 Medium 2023-06-07

This page lists every published CVE security advisory associated with ThemeFusion. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.